You currently have javascript disabled. Several functions may not work. Please re-enable javascript to access full functionality.

Register a free account to unlock additional features at BleepingComputer.com

Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Cid Pop Ups

and trying to remove it. i have now arrived at this point.. and it tells me to paste the log report. so here is it .. the problem started when i downloaded a handwriting facility for msn .and now i keep getting the pop up after pop up for CiD if that helps at all.

Click on Start>Control Panel>Add/Remove Programs.Uninstall/remove any of the following programs if listed:NetpumperBitrollBitgrabberCiD Help / CiD ManagerDownload Plugin for Internet ExplorerZone MediaThis is because they are often bundled with the malware you are dealing with.Don't worry if none of them are present.If you happened to remove any of them please restart your pc.

* First close any other programs you have running as this will require a reboot. * Double click NoLop.exe to run it. * Then click the button labelled "Search and Destroy". * When scanning is finished you will be prompted to reboot only if infected,click 'OK'. * Now click the "REBOOT" Button. * A Message should popup from NoLop, if not,double click the program again and it will finish. Post the contents of C:\NoLop.log and a new Hijack This log into your next reply.

Once the updates have been installed,do the following:Select the 'Scanner' icon at the top of the screen, then select the 'Settings' tab. Once in the 'Settings' screen,under 'How to act?',then under 'Set default action for detected malware to:', click on 'Recommended actions',then click on 'Quarantine'.Under 'Reports' select 'Automatically generate report after every scan' and unselect 'Only if threats were found'. Exit AVG Anti-Spyware,don't run the scan just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method. To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following [If still present], by placing a check in the appropriate boxes and selecting 'Fix checked'. Make sure all browser and all Windows Explorer windows are closed before fixing:

sorry for the delay night time called and I have got a friend around today to make sure i didnt make any mistakes. Please find below the AVG report you asked for however I seem to have lost the Hijack this copy when I rebooted. (Sorry)

Thank you for your help at this point no pop up has occured in the last hour.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. Make sure all browser and all Windows Explorer windows are closed before fixing:O4 - HKCU\..\Run: [curbremote] C:\DOCUME~1\HP_ADM~1\APPLIC~1\BIRDSE~1\metabindpop.exeExit Hijackthis.

***************************

Reboot your computer into SAFE MODE using the F8 method. To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Clear your 'System Restore' points by doing the following: Right-click on 'My Computer' and select 'Properties'. Select 'System Restore'. Select 'Turn Off System Restore On All Drives'. Select 'Apply'. You will then get the following warning:"You have chosen to turn off System Restore.If you continue,all existing restore points will be deleted,and you will not be able to track or undo changes to your computer.Do you want to turn off System Restore?".Then select 'Yes',your 'System Restore' directories will be purged.

Create a new 'System Restore' point:Click on Start/All Programs/Accessories/System Tools/System Restore. In the 'System Restore' window,click 'Create a Restore Point' button,then click 'Next'. In the window that appears,enter a description,then click on 'Create',then click 'Close'. The date and time is created automatically.

Please Note:Your version of Sun Java is out of date.Older versions have vulnerabilities that malware can use to infect your system.Please follow these steps to remove older versions of Sun Java,and then update.1. Download the latest version of Java Runtime Environment (JRE)2. Scroll down to where it says 'Java Runtime Environment (JRE) 6.0'.3. Click the "Download" button to the right.4. Check the box that says: "Accept License Agreement".5. The page will refresh.6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.7. Close any programs you may have running - especially your web browser.8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.10. Click the Change/Remove button.11. Repeat as many times as necessary to remove each Java versions.12. Reboot your computer once all Java components are removed.13. Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter.
Everyone else please begin a New Topic.